CVE-2017-20217 is an information disclosure vulnerability affecting Serviio PRO 1.8, caused by improper access control in its Configuration REST API. Unauthenticated remote attackers can exploit this by sending specially crafted requests to access sensitive configuration data. Rated with a CVSSv3 score of 7.5 (HIGH), this vulnerability has a network attack vector and low attack complexity, requiring no privileges or user interaction, with a high impact on confidentiality. There is currently no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB, and it has received no significant community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Serviio | Serviio PRO | 1.6.1, 1.7.0, 1.7.1, 1.8.0.0 PROCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.